
ds4kb (ds4kb) asked a question.
Disconnect users from on-prem Active Directory and integrate Azure AD as IdP instead.
The current setup - Our users and security groups are imported from our on-premises Active Directory. And we also use Microsoft Office 365 with Azure AD Connect in a hybrid identity situation that syncs users from the same Active Directory(one way sync) to the Azure AD tenant that serves O365.
We would like to eliminate the on-premises Active Directory server and rely completely on Azure cloud services instead. So moving forward we would like to continue using Okta to access our apps, but we want Okta to rely on Azure AD as its source for user identities. We will also turn off directory synchronization and convert our Azure AD synchronized users to cloud-only.
Can someone familiar with this type of change provide help with strategy, steps to follow, articles, or theory?
1) would it create duplicate (usernames)?
2) can I create azure to okta while still having active directory.
3) can I disconnect active directory sync

Hi @ds4kb (ds4kb) , Thank you for reaching out to the Okta Community!
To quickly answer your question:
That being said, there are a lot of moving parts and you have to know your entire environment and consider potential downstream implications and downtime, including but not limited to the following examples:
I'll leave this question open for the Community to share their advice and experiences as well, but I would also recommend you discuss this change with your Okta Account Executive or Customer Success Manager.
If my answer helped, remember to mark it as best to increase its visibility for other members of the Okta Community who might have the same questions as you.
Hope my answer helps!
--------------------------------
Community members help others by clicking Like or Select as Best on responses. Try it today.